Legacy DB security-group source range needs review

Base database source ranges on required clients, not only the number of addresses.

Description

A broad DB security-group CIDR can allow addresses beyond the applications and administrators that need a connection. A private address range does not make every system in it trusted.

A longer prefix reduces the address count, but no prefix length alone guarantees appropriate access. Restrict the range using actual clients and connection paths.

Potential impact

  • Systems without a business need may attempt database connections.
  • Accumulated broad exceptions make allowed clients and change impacts harder to track.

Remediation

  • Identify actual client addresses and administration paths, then allow only the required scope.
  • In current VPC security groups, use application security groups as sources where appropriate and restrict actual database ports.
  • Manage exception owners and expiry dates, and verify required connections and blocked access after changes.

Examples

These are historical DB Security Group CIDR comparisons. The resource was removed in Terraform AWS provider 5.0. Use VPC security groups for current environments and choose ranges for the actual approved clients.

Before

hcl
resource "aws_db_security_group" "db_sg" {
  name = "rds_sg"

  ingress {
    cidr = "10.0.0.0/24"
  }
}

10.0.0.0/24 contains 256 IPv4 addresses. Check whether each needs database access.

After

hcl
resource "aws_db_security_group" "db_sg" {
  name = "rds_sg"

  ingress {
    cidr = "10.0.0.0/25"
  }
}

10.0.0.0/25 contains 128 IPv4 addresses. A smaller range still needs unnecessary addresses excluded.

References